[apparmor] 4.17 net compat patches

John Johansen john.johansen at canonical.com
Wed Jul 11 05:28:40 UTC 2018


The v2.x network compatibility patches are finally up in what I hope is their final form in the kernel.org git
    git://git.kernel.org/pub/scm/linux/kernel/git/jj/linux-apparmor

    branch: git://git.kernel.org/pub/scm/linux/kernel/git/jj/linux-apparmor

and the 
    kernel-patch/v4.17/ directory in the apparmor repo on gitlab.
    https://gitlab.com/apparmor/apparmor/tree/master/kernel-patches/v4.17

These patches are provided for distros and users who used the older v2.x networking patches, and will never be upstreamed.

The first patch
    apparmor: patch to provide compatibility with v2.x net rules

can be used on its own if af_unix mediation was never used. The last 2 patches
    apparmor: af_unix mediation
    apparmor: fix use after free in sk_peer_label

are needed for af_unix mediation compatibility



More information about the AppArmor mailing list